Medium severity6.5NVD Advisory· Published Aug 5, 2021· Updated Jun 17, 2026
CVE-2021-29975
CVE-2021-29975
Description
Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or formatting, could be overlaid on top of another domain (with the new domain correctly shown in the address bar) resulting in possible user confusion. This vulnerability affects Firefox < 90.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5<90+ 2 more
- (no CPE)range: <90
- (no CPE)range: unspecified
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <90.0
- osv-coords2 versionspkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweed
< 128.5.1-1.1+ 1 more
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 92.0-1.2
Patches
Vulnerability mechanics
References
3- bugzilla.mozilla.org/show_bug.cginvdExploitIssue TrackingVendor Advisory
- security.gentoo.org/glsa/202202-03nvdThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2021-28/nvdVendor Advisory
News mentions
0No linked articles in our index yet.